Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Risk and Compliance
  4. Data on demand: Germany's Intelligence Services Reform Act and the new obligations for carmakers, platforms and banks
4MIN

Data on demand: Germany's Intelligence Services Reform Act and the new obligations for carmakers, platforms and banks

Aug 24 2026

Against a backdrop of intensifying hybrid threats – cyber-attacks, sabotage, disinformation and other covert pressure short of armed conflict – Germany is overhauling its intelligence services law. On 12 August 2026 the federal cabinet passed a reform package (Nachrichtendienstreformgesetz – NDRefG), centred on amendments to the Federal Constitutional Protection Act and the Federal Intelligence Service Act. At more than 730 pages, it would for the first time allow the domestic and foreign services to intervene operationally at home rather than merely observe.

The reform imposes, more quietly, new regulatory compliance requirements for the private sector, including disclosure, confidentiality and precautionary duties for car manufacturers, digital service providers and payment institutions. 

From information-gathering to operational intervention

The Federal Office for the Protection of the Constitution (BfV) and the Federal Intelligence Service (BND) are to be permitted to penetrate hostile actors' IT systems, disrupt or shut down servers used by state-sponsored hacker groups and even enter private homes to disable dangerous devices. Both are also to make far greater use of automated analysis and AI in evaluating personal data, with AI-generated findings capable of triggering the redirection, deletion or blocking of data traffic. The BfV could also access private IT systems of uninvolved third parties and intercept interpersonal telecommunications – calls, SMS and web-based calls – in certain cases without the prior oversight body authorisation envisaged in earlier versions.

Constitutional lawyers regard these provisions as the most exposed, calling the expansion of domestic powers vulnerable and predicting litigation once the law is in force. Civil-liberties organisations warn of a "massive increase in the power of the intelligence services" and a fundamental break with Germany's separation of intelligence and police functions.

New disclosure obligations for carmakers, digital services and payment providers

The draft also creates “request and disclosure” regimes that reach directly into the private sector. On the domestic side, these obligations sit in a single new provision on mandatory requests to commercial service providers; the Federal Intelligence Service Act mirrors that architecture for the foreign service. Three groups of addressees stand out. 

Automotive manufacturers and workshops

Car manufacturers – and, secondarily, workshops – are to become addressees of BfV requests for vehicle telemetry data, with the more intrusive requests channelled through a separate, higher-threshold procedure. The memorandum names, among others:

  • location, speed, mileage and usage data (e.g. ignition cycles, driving profiles)
  • sensor data such as seat occupancy and fuel-tank level

Digital service providers

Additionally, the draft  targets data of “digital services” in the broad sense of the Digital Services Act, i.e. video platforms, blogs, social media, search engines and online games. What may be demanded is tiered: At first level, subscriber data (the identity behind an account) could be retrieved. Usage data and content of use are to be regarded in cases of “qualified requests” only, requiring a materially stronger justification. Cloud-computing services are subject to a yet stricter regime. Requests for passwords and other credentials remain tied to separate statutory prerequisites.

The digital industry has pushed back hard, citing conflicts with EU data protection law, the equation of sensitive content data with basic subscriber data, an imprecise "digital services" definition, overbroad IT-system-copy duties, unrealistic response times and a self-defining "necessity for investigation" test.

Payment and financial services providers 

Technical payment services and entities with anti-money-laundering obligations are to become BfV addressees, too. Whilst primarily targeted at banks, the draft also creates duties for card networks when card-issuing banks sit abroad. A related amendment to the Anti-Money Laundering Act would let obliged entities record a pseudonymised or “legended” counterparty identity – to disguise the services’ own payment infrastructure and operatives’ cover, not to protect surveillance targets.

Secondary obligations matter as much as the request powers:

  • a strict confidentiality duty barring addressees from informing customers or third parties, even under statutory reporting duties, plus a non-retaliation prohibition;
  • compensation based on the statutory scale for witnesses and experts with the risk not to cover all costs; and
  • an administrative fines regime for disclosure-duty breaches, alongside criminal liability for confidentiality breaches, with enforcement supervised along the lines of the telecommunications regime.

Outlook: Short timeline for Parliament and the Federal Council

The Constitutional Court's October 2024 ruling gives lawmakers until 31 December 2026 to restore constitutionally compliant oversight, which is also to be restructured by the draft. This gives the co-legislators only a few months to debate the concerns raised by associations and companies. The first Federal Council session is set to take place on 25 September 2026, while discussions in the Federal Parliament will begin in the same week and are likely to conclude at the end of November. 18 December 2026 is the last possible date for the Federal Council to have its final say. Whilst passing the law in time seems ambitious but likely at the current stage, failure to agree by the end of the year risks yet another reaction from the Constitutional Court.

Tags

data cybersecurity and tech regulationautomotivetechnologyfinancial servicesdigital infrastructuregermany

Authors

Berlin

Alex Schmidtke

Head of Public Affairs
Düsseldorf

Christoph Werkmeister

Global Co-Head of Data & Technology
Düsseldorf

Christian Sosna

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome